← Back to list

Liability and Law in the Age of Autonomous Vehicles

Karl Saamuel Hollman

Karl Saamuel Hollman in TalTech Legal Lab Blog · 2026-05-20 12:38 · 0 claps · 8.3 min read
#self-driving-cars #liability-and-law #autonomous-vehicles
Open on Medium ↗
Wiki topics: LLM · Large Language Models AGT · AI Agents ML · Machine Learning ⚖️ · Law & Justice

Image from the Magnific collection

Image from the Magnific collection

Liability and Law in the Age of Autonomous Vehicles

Karl Saamuel Hollman

The self-driving car has crossed from science fiction into legal reality. Modern vehicles already incorporate lane-keeping assistance, adaptive cruise control, automated emergency braking, parking systems, and increasingly sophisticated driving automation. Yet the central question that will define the next era of road traffic law remains unresolved: when an autonomous vehicle causes an accident, who bears responsibility?

This question has no simple answer, because road traffic law was built around the human driver. A driver observes the road, makes decisions, reacts to danger, and can be held liable for negligence if they fall below a reasonable standard. Autonomous vehicles fundamentally disrupt this model. When a car accelerates, brakes, changes lanes, or fails to detect an obstacle because of software logic, sensor failure, or machine-learning behaviour, responsibility no longer maps cleanly onto a single individual.

The challenge is not simply that autonomous vehicles are new technology. It is that they transform driving from an individual human act into a distributed technological system involving manufacturers, software developers, component suppliers, data providers, owners, operators, insurers, and regulators. Liability must be rethought accordingly.

From Human Error to System Failure

Conventional accident law works through familiar categories: negligence, traffic violations, product defects, or some combination of these factors. A human driver may be liable for speeding, distraction, or failure to keep a proper lookout. A manufacturer may be liable if defective brakes or airbags contributed to the harm. The vehicle, in this model, is an instrument under human control.

Autonomous vehicles collapse this distinction. The vehicle may itself be making operational decisions and the “driver” may not be driving at all. The critical question then becomes whether an accident was caused by human misuse, defective design, faulty software, inadequate warnings, a cybersecurity failure, unreliable mapping data, or some combination of all of these.

This is why the phrase “self-driving car” is legally imprecise. Vehicles exist on a spectrum of automation. Some systems assist the driver without removing human control; others assume full operational responsibility under specific, defined conditions. UNECE Regulation №157 on Automated Lane Keeping Systems, for example, establishes technical standards for performance, human-machine interaction, and safety across different automation levels (UNECE, 2021, 2023). The legal consequences of a crash depend heavily on where on that spectrum control actually lay at the time of the accident.

A Web of Potential Liability

In any accident involving an autonomous vehicle, liability may fall on several actors and often on more than one simultaneously.

The human driver or user may remain liable where they ignored system warnings, used automation outside its approved operating conditions, or failed to resume control when required. If a lane-keeping system is designed exclusively for motorway use but the driver activates it on an urban road, the human user may be primarily responsible for the consequences.

The vehicle manufacturer may be liable if the vehicle was defectively designed, failed to meet regulatory requirements, or incorporated unsafe decision-making logic. The software developer may bear responsibility where faulty code, a defective update, or a machine-learning failure caused the accident. Component suppliers may be implicated if a sensor, camera, lidar unit, radar system, or chip malfunctioned. Data and map providers may become relevant if the vehicle relied on inaccurate or outdated infrastructure information.

In practice, liability will rarely rest with a single actor. A realistic accident scenario may involve overlapping failures: a driver who overtrusted the technology, a manufacturer that overstated its capabilities, and software that broke down in a foreseeable edge case. The law must be capable of distributing responsibility across this entire ecosystem.

Product Liability: The Algorithm as Part of the Vehicle

One of the most significant legal developments for autonomous vehicles is the modernisation of product liability law. Traditional product liability was designed for physical goods: a defective brake, an exploding battery, a faulty steering rack. Autonomous vehicles demand that the law treat software, AI systems, and ongoing digital updates as legally integral parts of the product.

The EU’s revised Product Liability Directive, Directive (EU) 2024/2853, modernises the older liability framework to address digital-age products, including software and AI-enabled systems (European Parliament and Council of the European Union, 2024a). Published in November 2024, entering into force in December 2024, and requiring national transposition by December 2026, the Directive establishes that defective software can make a product unsafe in precisely the same way a defective brake can.

Equally important is the Directive’s approach to evidence. Autonomous vehicle accidents create a deep information asymmetry: the manufacturer holds system logs, training data, internal safety tests, and post-accident diagnostics; the injured person typically has none of this. The new framework is designed to address exactly this problem, making liability workable where complex technology and unequal access to information would otherwise leave victims without a realistic path to compensation.

Negligence and the “Reasonable Driver” Problem

Negligence law asks whether someone failed to exercise reasonable care. For autonomous vehicles, this immediately raises a harder question: reasonable compared to whom?

If a human driver fails to brake for a pedestrian, courts can compare their conduct to that of a reasonable driver. But if an automated system fails to classify a pedestrian correctly, should the standard of comparison be a reasonable human driver, a reasonable manufacturer, a reasonable software engineer, or a reasonable autonomous system? The question is not merely theoretical: it determines who is being judged, and by what standard.

Autonomous systems perceive the world very differently from humans. They depend on sensors, classification models, prediction algorithms, and programmed risk thresholds. They may outperform humans in some scenarios, reacting faster to sudden braking, for example, while underperforming in others, such as interpreting an ambiguous hand gesture from a cyclist or navigating an unexpected social situation.

For this reason, negligence analysis in autonomous vehicle cases cannot focus only on the moment of the crash. It must examine the longer arc of organisational conduct: Was the system adequately tested? Were foreseeable edge cases considered? Were safety limitations clearly communicated? Was post-market performance monitored? Were software updates deployed responsibly? Were cybersecurity risks managed? The legal focus shifts from the split-second decision of a driver to the sustained conduct of the organisations that designed, trained, certified, updated, and sold the system.

Regulation Before the Accident

Liability law compensates for harm after it occurs. Regulation attempts to prevent harm before it does.

In Europe, autonomous vehicle regulation is the product of several overlapping instruments: UNECE technical standards, EU type-approval rules, the General Safety Regulation, the AI Act, and cybersecurity and software update requirements. Regulation (EU) 2024/1689, the AI Act, establishes a horizontal risk-based framework for AI systems placed on the EU market (European Parliament and Council of the European Union, 2024b). Since autonomous vehicles depend on AI for perception, prediction, and decision-making, the Act’s obligations are directly relevant.

The AI Act is, however, primarily a compliance framework: it defines what a system must do to be lawfully deployed, but it does not itself create a civil liability regime. For accident compensation, the revised Product Liability Directive is the more directly relevant instrument. The two work in tandem. The AI Act sets safety and transparency standards before deployment. Product liability law enables victims to claim compensation after harm occurs. Together, they illustrate the fundamental principle that no single legal instrument can regulate autonomous vehicles alone.

The Problem of the Handover

Among the most legally sensitive scenarios is the transition between automated and human control. Many current vehicles are not designed for full autonomy in all conditions: they may operate independently only on certain roads, within certain speed ranges, in specific weather, or under particular traffic conditions. When the system reaches the boundary of its operational domain, it typically prompts the human to take back control.

This handover creates difficult liability questions. How much notice must the system give? What if the driver has become inattentive precisely because the system encouraged them to disengage? What if the handover prompt is ambiguous, or fails entirely? What if the driver was misled by marketing that presented the system as more capable than it is?

In these circumstances, attributing responsibility solely to the human driver may be unjust. If the system design encourages overreliance, or if the product was marketed in ways that created unrealistic expectations, the manufacturer must bear a share of the responsibility. The more capable a system appears, the more users will trust it, and the greater the duty on those who built it to ensure that trust is warranted.

Data as Evidence

Autonomous vehicles generate vast quantities of data. Before and during an accident, a vehicle may record speed, braking input, steering angle, sensor readings, software status, driver attention levels, active automation modes, and system warnings. This data has the potential to make accident reconstruction far more precise than it has ever been for human-driven vehicles.

But data access raises its own legal problems. Who owns and controls the data? Can injured parties access it? What retention obligations apply? Can manufacturers selectively disclose only favourable records? How should privacy be protected when vehicle data may reveal location history, behavioural patterns, passenger identities, and biometric information from driver-monitoring systems?

A functioning liability regime requires reliable access to technical evidence. Without it, responsibility cannot be assigned fairly. At the same time, data access must be governed carefully to prevent misuse. These competing demands, transparency for accountability, privacy for individuals, require their own legal framework, one that has not yet fully emerged.

Conclusion: Liability Follows Control

Autonomous vehicles do not abolish liability. They relocate it. The question is not whether someone should be responsible when an autonomous vehicle causes harm, of course they should. The question is which actor, or actors, that responsibility should fall upon.

The most defensible principle is this: liability should follow control, knowledge, and risk creation. Where the human was genuinely driving and made an error, human liability remains appropriate. Where the automated system was in control and failed under conditions it was designed to handle, liability should shift toward the manufacturer, software developer, or relevant product supplier. Where the harm resulted from defective updates, cybersecurity failures, or negligent post-market oversight, responsibility should attach to whoever controlled those risks.

This principle has a deeper logic. The actor best positioned to prevent a harm should bear the legal burden when that harm materialises. Manufacturers who profit from autonomous technology, who control its design and testing, who hold its data and understand its limits, are in the best position to prevent system failures. They should not be able to externalise the costs of those failures onto injured victims, or onto a human “driver” whose primary role was to sit in a seat.

The legal frameworks emerging in Europe, the revised Product Liability Directive, the AI Act, UNECE technical standards, represent a serious attempt to confront this challenge. But law moves more slowly than technology. The most important work ahead is not simply adapting old rules to new vehicles. It is building legal institutions capable of assigning responsibility fairly in a world where the driver is increasingly an algorithm.

References

Alawadhi, M., Almazrouie, J., Kamil, M., & Khalil, K. A. (2020). Review and analysis of the importance of autonomous vehicles liability: A systematic literature review. International Journal of System Assurance Engineering and Management, 11(6), 1227–1249.

https://doi.org/10.1007/s13198-020-00978-9

Buiten, M. C. (2024). Product liability for defective AI. European Journal of Law and Economics, 57(1), 239–273. https://doi.org/10.1007/s10657-024-09794-z

European Parliament and Council of the European Union. (2019). Regulation (EU) 2019/2144 of the European Parliament and of the Council of 27 November 2019 on type-approval requirements for motor vehicles and their trailers, and systems, components and separate technical units intended for such vehicles, as regards their general safety and the protection of vehicle occupants and vulnerable road users. Official Journal of the European Union.

European Parliament and Council of the European Union. (2024a). Directive (EU) 2024/2853

of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC. Official Journal of the European Union.

European Parliament and Council of the European Union. (2024b). Regulation (EU)

2024/1689 of the European Parliament and of the Council of 13 June 2024 laying downharmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.

Gless, S., & Ligeti, K. (2023). Regulating driving automation in the European Union –

Criminal liability on the road ahead? New Journal of European Criminal Law.

https://doi.org/10.1177/20322844231213336

Hacker, P. (2023). The European AI liability directives — Critique of a half-hearted approach and lessons for the future. Computer Law & Security Review, 51, 105871.

https://doi.org/10.1016/j.clsr.2023.105871

United Nations Economic Commission for Europe. (2021). UN Regulation №157:

Automated Lane Keeping Systems. UNECE.

United Nations Economic Commission for Europe. (2023). UN Regulation №157: Uniform

provisions concerning the


메타데이터
post_id
3c22caa59dd4
slug
liability-and-law-in-the-age-of-autonomous-vehicles-3c22caa59dd4
url
https://medium.com/taltech-legal-lab/liability-and-law-in-the-age-of-autonomous-vehicles-3c22caa59dd4
canonical_url
https://medium.com/taltech-legal-lab/liability-and-law-in-the-age-of-autonomous-vehicles-3c22caa59dd4
author_url
https://medium.com/@karlsaamuelh
status
ok
fetched_at
2026-06-14 11:28:49