top of page
Search

Regulating the Invisible Driver: Reconceptualizing Vicarious Liability and Negligent Supervision for Autonomous Vehicles

Caroline Rollheiser

Autonomous driving pushes centuries-old tort and agency doctrines into unfamiliar territory. When a self-driving truck barrels through a red light[1] or a robotaxi clips a cyclist,[2] the injured plaintiff still wants to know: who must pay? Vicarious liability can help to answer this question by transferring the autonomous vehicle’s (“AV”) torts to the deployer. Additionally, negligent supervision imposes primary fault for carelessly entrusting a dangerous instrumentality to another. Courts and legislators must now decide whether these longstanding doctrines can extend to injuries inflicted by machines that act with genuine autonomy from direct human control.
           
Vicarious liability rests on an agency relationship, meaning someone acts for and under the control of another[3] and, in doing so, injures a third party.[4] AVs fit within this framework because although the car lacks consciousness, it functions as a “surrogate agent” whose purposive behavior is directed entirely toward advancing its deployer’s interests.[5] The Uniform Electronic Transactions Act already treats software this way, describing a computer program that transacts without human review as a “tool” of its user.[6] The user, not the software, assumes responsibility for the outcome.[7] Thus, a well-developed pure agency theory for AVs finds no conceptual barrier to holding the companies that unleash these machines on public roads liable for any torts they commit.
           
Courts have long used the concept of instrumentalities to resolve questions about who bears legal responsibility. In Brouse v. U.S.,[8] a 1949 crash was caused by an aircraft on “robot control.”[9] The Court placed fault squarely on the human pilot for failing to keep lookout, reasoning that the obligation to supervise did not vanish simply because the aircraft flew itself part of the time.[10] The robot-controlled plane in Brouse can serve as an analogy for AVs, depending on the level of human control. There are six levels of autonomous driving, from Level 0 to Level 5.[11] Level 0 offers no automation while Level 1, which is now common in newer cars, provides single assist (e.g., cruise control or lane-centering) but keeps the driver fully responsible, hands-on, and ready to intervene at all times.[12] At Level 2, advanced driver-assistance systems handle steering and speed, but the driver must stay alert and ready to take control.[13] Level 3 is a rare conditional level that allows the car to drive itself without driver input, but only at set speeds, on specific roads, and within defined, geo-fenced conditions.[14] In Level 4, the car still has a steering wheel and pedals, yet it can drive itself without any driver attention.[15] Today, driverless taxis already operate at this level, moving between set points inside geo-fenced zones, though heavy rain or other harsh weather can suspend service.[16] At Level 5, the car is fully self-driving.[17] It has no steering wheel or pedals, so human input is entirely removed.[18] 
 
Extending Brouse, liability should follow the actor capable of meaningful supervision at the relevant automation level. Under Level 2 and Level 3 driver-assist technology, a fleet owner who instructs a safety operator to stay alert may still face respondeat superior liability if that operator drifts off and a crash occurs. However, the Brouse analogy weakens as automation approaches Level 4 and Level 5. Because human safety drivers cannot feasibly seize control at these levels, scholars now describe this setup as a “moral crumple zone” that funnels blame onto the monitor, allowing the company to evade liability.[19] When genuine oversight cannot be exercised, a court may conclude that the party that designed, tested, and deployed the software is the most appropriate loss bearer, echoing the same policy rationale that underpins traditional vicarious liability.[20] 
           
Negligent supervision[21] offers a parallel pathway to recovery. Even if the car drives itself, the owner or remote operator still controls when to activate it, how often to update its software, and whether to add safety features like driver-monitoring cameras.[22] Deployers who disable safety features, ignore warning data, or release software that struggles in rain or construction zones can be likened to engineers who send a train onto the tracks after removing its brakes, recklessly entrusting public safety to a system patently unprepared for real-world hazards.[23] As AI becomes harder to understand, critics will likely increasingly argue that simply putting these systems on the road is negligent, particularly when data reveal they stumble in tricky situations like blocked sensors or bad sensor fusion.[24]
           
Legislation in this area is relatively recent.[25] Colorado’s 2017 bill authorizes Level 4 and Level 5 vehicles so long as their automated systems comply with every traffic rule, yet it assigns crash responsibility to “state law, federal law, or common law,” leaving judges to decide whether traditional vicarious liability, product defect, or some combination should apply.[26] Nevada goes a step further by redefining “driver” to include both the owner of a fully autonomous car and the person who engages the system, thereby signaling that traditional operator-centric tort duties now rest on the entity that triggers autonomy.[27] New York, conversely, insists a licensed human sit behind the wheel during testing and even requires state-police supervision, an approach clearly designed to preserve a human focal point for negligence suits.[28] At the federal level, the National Highway Traffic Safety Administration has issued advisory guidance and rolled out multi-billion-dollar initiatives, yet it still has not adopted binding performance standards that would unify the existing patchwork of state regulations.[29] With a regulatory gap in place, courts are more likely to rely on common law principles than wait for Congress to step in.
           
Extending vicarious liability to machine conduct promotes compensation and deterrence but raises countervailing concerns. Developers warn that open-ended exposure could chill innovation,[30] raise insurance premiums,[31] and slow development of a technology that promises to slash crash rates relative to human drivers.[32] Some commentators propose a no-fault compensation fund modelled on the National Vaccine Injury Compensation Program,[33] arguing that the social gains from widespread automation justify spreading losses across all beneficiaries rather than pinning them on a single unlucky manufacturer.[34] Others advocate for strict enterprise liability, contending that guaranteed compensation is essential for preserving public trust in streets shared with algorithmic drivers.[35] How courts decide to expand existing doctrines or demand new legislation will depend on how they balance deterrence, innovation, and fair compensation for victims.
           
Several key doctrinal questions still remain. First, the very identity of the “driver” fluctuates across jurisdictions, complicating cross-state fleet management and insurance pricing.[36] Second, courts must determine the standard for reasonable supervision when a human overseer cannot foresee, or even comprehend, every decision made by a black-box[37] neural network.[38] Third, the line between a product defect and negligent supervision is blurry. For example, if an AV crashes in heavy rain, was the root cause a design flaw, inadequate training data, or poor monitoring?[39] Fourth, once federal safety standards are in place, courts will need to decide whether state tort duties that go beyond those regulations are preempted. Fifth, proving causation hinges on access to detailed sensor recordings and machine-learning logs. Without compulsory data-driven rules or presumptions that missing data cut against the holder, plaintiffs may struggle to satisfy even a basic negligence showing.[40] While these gaps do not doom traditional tort theory, each will need careful tailoring to keep the law in step with advancing technology.
           
Although autonomous decision-making is new, existing tort and agency doctrines have already shown themselves to be remarkably adaptable. Treating the AV as an agent or employee reflects the reality that it carries out its deployer’s agenda, not any self-originated impulses.[41] Viewing deployment as an arrangement with non-delegable duties places liability on the party best equipped to bear and manage the risk.[42] Negligent supervision stops developers from shifting blame to the black-box code they selected, trained, or disregarded.[43] Because federal regulators have stayed on the sidelines, states have begun testing varied operator definitions and oversight rules, leaving courts to refine the law case by case. As cases trickle in, judges will return to tort law’s central inquiry: who could have avoided the harm at the least cost?[44] Given that companies design and profit from autonomous systems, judges are likely to keep viewing them as the ultimate risk bearers.  
           
The central policy challenge is to navigate between two dangers: too little deterrence, which could leave crash victims without a responsible defendant, and too much deterrence, which could keep potentially life-saving automation stuck in perpetual testing. A mix of vicarious liability and negligent supervision doctrines, supplemented by robust data-access requirements and possibly an insurance safety net for major losses, can achieve that equilibrium. In the meantime, lawyers, lawmakers, and scholars must update the language that this centuries-old body of law will use to address a distinctly twenty-first century driver.

 

 

 


[1] Waymo Self-Driving Car Runs Red Light Raising Safety Concerns, DigWatch (Jul. 8, 2024), https://dig.watch/updates/waymo-self-driving-car-runs-red-light-raising-safety-concerns.
[2] Waymo Robotaxi Accident with San Francisco Cyclist Draws Regulatory Review, Reuters (Feb. 8, 2024), https://www.reuters.com/world/us/driverless-waymo-car-hits-cyclist-san-francisco-causes-minor-scratches-2024-02-07/.
[3] Restatement (Third) of Agency § 1.01 (2006) (“Agency is the fiduciary relationship that arises when one person (a ‘principal’) manifests assent to another person (an ‘agent’) that the agent shall act on the principal's behalf and subject to the principal's control, and the agent manifests assent or otherwise consents so to act.”).
[4] Id. § 7.07 (“An employer is subject to vicarious liability for a tort committed by its employee acting within the scope of employment.”).
[5] Pinchas Huberman, A Theory of Vicarious Liability for Autonomous-Machine-Caused Harm, 58 Osgoode Hall L. J. 233, 270 (2021); Information Technology and Moral Philosophy 251 (Jeroen van den Hoven & John Weckert eds., 2009) (computer systems’ agency is akin to surrogate agents because “[they] are designed and deployed to do tasks assigned to them by humans.”).
[6] Unif. Elec. Transactions Act § 2 cmt. 5, 7A U.L.A. 48 (1999) (“An electronic agent, such as a computer program or other automated means employed by a person, is a tool of that person.”).
[7] Id. (“As a general rule, the employer of a tool is responsible for the results obtained by the use of that tool since the tool has no independent volition of its own . . . .  An electronic agent, by definition, is capable within the parameters of its programming, of initiating, responding or interacting with other parties or their electronic agents once it has been activated by a party, without further attention of that party.”).
[8] 83 F.Supp. 373 (N.D. Ohio 1949).
[9] Id. at 374.
[10] Id. (“The obligation of those in charge of a plane under robot control to keep a proper and constant lookout is unavoidable.”).
[11] Peter Nelson, The Six Levels of Autonomous Driving, Explained, J.D. Power (Feb. 14, 2025), https://www.jdpower.com/cars/shopping-guides/levels-of-autonomous-driving-explained.
[12] Id.
[13] Id.
[14] Id.
[15] Id.
[16] Id.
[17] Id.
[18] Id.
[19] Gary Marchant & Rida Bazzi, Autonomous Vehicles and Liability: What Will Juries Do?, 26 B.U. J. Sci. & Tech. L. 67, 94 (2020).
[20] Dr. Deepak Dumar Sahoo, Vicarious Liability: A Solution to a Problem of AI Responsibility, 4 J. Informatics Educ. & Rsch. 1808, 1810 (2024) (“[W]ithout a clearly identified wrongdoer . . . . [m]anufacturers emerge as appropriate bearers of responsibility.”); Drones, Robots, and Driverless Vehicles, GSB Legal (Mar. 13, 2017), https://www.gsblegal.com/drones-robots-and-driverless-vehicles/ (“The person who owns an artificially intelligent device is arguably in the best position to decide whether it is reasonably safe to hit the ‘On’ button, and should therefore bear the risk of anything that happens after that button has been pushed.”).
[21] Restatement (Third) of Agency § 7.05(1) (2006) (“A principal who conducts an activity through an agent is subject to liability for harm to a third party caused by the agent's conduct if the harm was caused by the principal's negligence in selecting, training, retaining, supervising, or otherwise controlling the agent.”).
[22] K.C. Webb, Products Liability and Autonomous Vehicles: Who’s Driving Whom?, 23 Rich. J. L. & Tech. 1, 9 (2017); Marchant & Bazzi, supra note 19, at 94–95.
[23] Marchant & Bazzi, supra note 19, at 95–97.
[24] Id. at 75; Sophia H. Duffy & Jamie Patrick Hopkins, Sit, Stay, Drive: The Future of Autonomous Car Liability, 16 SMU Sci. & Tech. L. Rev. 453, 471 (2013).
[25] “Each year, the number of states considering legislation related to autonomous vehicles has gradually increased.” Autonomous Vehicles: Self-Driving Vehicles Enacted Legislation, Nat’l Conf. of State Legislatures, https://www.ncsl.org/transportation/autonomous-vehicles (Feb. 18, 2020). “Twenty-nine states—Alabama, Arkansas, California, Colorado, Connecticut, Florida, Georgia, Illinois, Kentucky, Louisiana, Maine, Michigan, Mississippi, Nebraska, New York, Nevada, North Carolina, North Dakota, Oregon, Pennsylvania, South Carolina, Tennessee, Texas, Utah, Virginia, Vermont, Washington and Wisconsin—and Washington D.C. have enacted legislation related to autonomous vehicles.” Id.
[26] S.B. 17-213, 71st Gen. Assemb., 1st Reg. Sess. (Colo. 2017). Colorado Governor Jared Polis recently vetoed H.B. 25-1122, which would have prohibited the use of self-driving commercial vehicles unless an individual who holds a commercial driver's license is inside at all times. Marissa Ventrelli, Governor Vetoes Measures on Self-Driving Vehicles, Copays for Inmates, Ambulance Costs, Colo. Politics (May 30, 2025), https://www.coloradopolitics.com/governor/polis-veto-bills-autonomous-vehicles-ambulance/article_9f354eb1-ebd7-4087-b545-5284b2a67033.html. Polis believed the bill could “undermine innovation of future technologies that could increase road safety.” Id.
[27] Assemb. B. 69, 79th Leg. (Nev. 2017). Nevada recently introduced S.B. 395, which would require a human operator to be on board in fully autonomous cars and would mandate manufacturers to maintain certain types of insurance to protect against the risk of damages caused by AV-related accidents. Joseph L. Benson II & Ben J. Bingham, Autonomy on Hold: Nevada Senate Bill SB395 to Hit the Brakes on Fully Driverless Vehicles, The Nat’l L. Rev. (May 29, 2025), https://natlawreview.com/article/autonomy-hold-nevada-senate-bill-sb395-seeks-hit-brakes-fully-driverless-vehicles.
[28] Assemb. B. A9508B, 2017-2018 Reg. Sess. (N.Y. 2018).
[29] Automated Driving Systems, NHTSA, https://www.nhtsa.gov/vehicle-manufacturers/automated-driving-systems (last visited May 31, 2025).
[30] Duffy & Hopkins, supra note 24, at 475 (“[T]raditional tort law routinely penalizes innovation, while rewarding manufacturers who adhere to the status quo.”).
[31] John Buchanan & Megan Mumford Myers, Insurance for Autonomous Vehicles: Who Will Drive Those Risks?, 69 The Prac. Law. 3, 11 (2023) (“Some commentators have opined that standalone cyber policies for AV fleets are likely to be very expensive because they involve catastrophic peril. Others have noted the challenge of pricing the risks of connected networks that could potentially result in widespread infrastructure damage from hacking by malicious actors.”).
[32] Marchant & Bazzi, supra note 19, at 84 (“[N]inety-four percent of motor vehicle crashes [are] due to human choice or error. Because Avs avoid these human errors, which account for the vast majority of vehicle accidents, Avs have the potential to be significantly safer overall than human-driven conventional vehicles.”).
[33] Health Res. & Servs. Admin., What You Need to Know About the National Vaccine Injury Compensation Program (VICP) 3 (2019) (explaining that, while vaccines are overwhelmingly safe, rare serious reactions are compensated through VICP, which provides compensation to people found to be injured by certain vaccines).
[34] Tracy Hresko Pearl, Compensation at the Crossroads: Autonomous Vehicles & Alternative Victim Compensation Schemes, 60 Wm. & Mary L. Rev. 1827, 1879 (2019) (“Much like the NVICP which is funded by a small tax on every covered vaccine administered to a patient, a sales tax on every Level 4 or 5 autonomous vehicle should finance an autonomous vehicle crash fund.”); Marchant & Bazzi, supra note 19, at 91 (noting that shifting accident costs to manufacturers spreads them across all users but, as the pre-1986 vaccine experience showed, large liability and punitive damages can still drive socially valuable products, like autonomous vehicles, off the market). See also Antonio Davola, A Model for Tort Liability in a World of Driverless Cars: Establishing a Framework for the Upcoming Technology, 54 Idaho L. Rev. 591, 609–14 (2018) (proposing a two-step system in which a public-private fund, financed partly by manufacturers’ market share and party by a federal tax, compensates victims when no negligence is found).
[35] Jacob D. Walpert, Carpooling Liability?: Applying Tort Law Principles to the Joint Emergence of Self-Driving Automobiles and Transportation Network Companies, 85 Fordham L. Rev. 1863, 1894 (2017) (arguing that ride-sharing and autonomous vehicle companies—deep-pocket enterprises that replace individual drivers—should face strict, enterprise-based liability, much like owners held vicariously liable for permissive drivers, because they can best spread accident costs and ensure victim compensation).
[36] See id. at 1886–88 (noting that state codes differ sharply on who qualifies as a “driver” or “operator,” so the definition varies by jurisdiction); Marchant & Bazzi, supra note 19, at 81–82.
[37] “A black box AI is an AI system whose internal workings are a mystery to its users. Users can see the system’s inputs and outputs, but they can’t see what happens within the AI tool to produce those outputs.” Matthew Kosinski, What is Black Box Artificial Intelligence (AI)?, IBM (Oct. 29, 2024), https://www.ibm.com/think/topics/black-box-ai.
[38] Daniela Glavaniĉová & Matteo Pascucci, Vicarious Liability: A Solution to a Problem of AI Responsibility?, 24 Ethics & Info. Tech. 1, 1 (2022) (“[T]he implemented operations guiding the behaviour of a machine often have a high degree of complexity, not allowing one to foresee all possible outcomes.”).
[39] See Marchant & Bazzi, supra note 19, at 88–93; Webb, supra note 22, at 26.
[40] See Marchant & Bazzi, supra note 19, at 98; Buchanan & Myers, supra note 31, at 12; Mythili Srinivasamurthy, Autonomous Vehicles and Complexities in Allocation of Liability, 1 Jus Corpus L. J. 360, 367 (2021).
[41] Huberman, supra note 5, at 283 (“AAs perform tasks for deployers with functional independence. In this sense, AAs’ social role is analogous to that of legal agents: AAs are instrumentally rational actors who act exclusively for human or corporate purposes. They do not have their own subjective interests that need to be restrained.”).
[42] See id. at 249; Walpert, supra note 35, at 1895; Peter Y. Kim, Where We’re Going, We Don’t Need Drivers: Autonomous Vehicles and AI-Chaperone Liability, 69 Cath. Univ. L. Rev. 341, 353 (2020).
[43] See Kim, supra note 42, at 352–54; Marchant & Bazzi, supra note 19, at 89–90; Huberman, supra note 5, at 237; Srinivasamurthy, supra note 40, at 364.
[44] Nuno M. Garoupa & Giuseppe Dari-Mattiacci, Least Cost Avoidance: The Tragedy of Common Safety, 25 J. L., Econ., & Org. 235, 235 (2007) (observing that liability should rest with the least-cost avoider, promoting efficient accident prevention and avoiding redundant or wasteful precautions).
 
 
 

Comments


bottom of page