Regulating the Invisible Driver: Reconceptualizing Vicarious Liability and Negligent Supervision for Autonomous Vehicles
- law-tlj
- Feb 2
- 12 min read
Caroline Rollheiser
Autonomous driving pushes centuries-old tort and agency doctrines into unfamiliar territory. When a self-driving truck barrels through a red light[1] or a robotaxi clips a cyclist,[2] the injured plaintiff still wants to know: who must pay? Vicarious liability can help to answer this question by transferring the autonomous vehicle’s (“AV”) torts to the deployer. Additionally, negligent supervision imposes primary fault for carelessly entrusting a dangerous instrumentality to another. Courts and legislators must now decide whether these longstanding doctrines can extend to injuries inflicted by machines that act with genuine autonomy from direct human control.
Vicarious liability rests on an agency relationship, meaning someone acts for and under the control of another[3] and, in doing so, injures a third party.[4] AVs fit within this framework because although the car lacks consciousness, it functions as a “surrogate agent” whose purposive behavior is directed entirely toward advancing its deployer’s interests.[5] The Uniform Electronic Transactions Act already treats software this way, describing a computer program that transacts without human review as a “tool” of its user.[6] The user, not the software, assumes responsibility for the outcome.[7] Thus, a well-developed pure agency theory for AVs finds no conceptual barrier to holding the companies that unleash these machines on public roads liable for any torts they commit.
Courts have long used the concept of instrumentalities to resolve questions about who bears legal responsibility. In Brouse v. U.S.,[8] a 1949 crash was caused by an aircraft on “robot control.”[9] The Court placed fault squarely on the human pilot for failing to keep lookout, reasoning that the obligation to supervise did not vanish simply because the aircraft flew itself part of the time.[10] The robot-controlled plane in Brouse can serve as an analogy for AVs, depending on the level of human control. There are six levels of autonomous driving, from Level 0 to Level 5.[11] Level 0 offers no automation while Level 1, which is now common in newer cars, provides single assist (e.g., cruise control or lane-centering) but keeps the driver fully responsible, hands-on, and ready to intervene at all times.[12] At Level 2, advanced driver-assistance systems handle steering and speed, but the driver must stay alert and ready to take control.[13] Level 3 is a rare conditional level that allows the car to drive itself without driver input, but only at set speeds, on specific roads, and within defined, geo-fenced conditions.[14] In Level 4, the car still has a steering wheel and pedals, yet it can drive itself without any driver attention.[15] Today, driverless taxis already operate at this level, moving between set points inside geo-fenced zones, though heavy rain or other harsh weather can suspend service.[16] At Level 5, the car is fully self-driving.[17] It has no steering wheel or pedals, so human input is entirely removed.[18]
Extending Brouse, liability should follow the actor capable of meaningful supervision at the relevant automation level. Under Level 2 and Level 3 driver-assist technology, a fleet owner who instructs a safety operator to stay alert may still face respondeat superior liability if that operator drifts off and a crash occurs. However, the Brouse analogy weakens as automation approaches Level 4 and Level 5. Because human safety drivers cannot feasibly seize control at these levels, scholars now describe this setup as a “moral crumple zone” that funnels blame onto the monitor, allowing the company to evade liability.[19] When genuine oversight cannot be exercised, a court may conclude that the party that designed, tested, and deployed the software is the most appropriate loss bearer, echoing the same policy rationale that underpins traditional vicarious liability.[20]
Negligent supervision[21] offers a parallel pathway to recovery. Even if the car drives itself, the owner or remote operator still controls when to activate it, how often to update its software, and whether to add safety features like driver-monitoring cameras.[22] Deployers who disable safety features, ignore warning data, or release software that struggles in rain or construction zones can be likened to engineers who send a train onto the tracks after removing its brakes, recklessly entrusting public safety to a system patently unprepared for real-world hazards.[23] As AI becomes harder to understand, critics will likely increasingly argue that simply putting these systems on the road is negligent, particularly when data reveal they stumble in tricky situations like blocked sensors or bad sensor fusion.[24]
Legislation in this area is relatively recent.[25] Colorado’s 2017 bill authorizes Level 4 and Level 5 vehicles so long as their automated systems comply with every traffic rule, yet it assigns crash responsibility to “state law, federal law, or common law,” leaving judges to decide whether traditional vicarious liability, product defect, or some combination should apply.[26] Nevada goes a step further by redefining “driver” to include both the owner of a fully autonomous car and the person who engages the system, thereby signaling that traditional operator-centric tort duties now rest on the entity that triggers autonomy.[27] New York, conversely, insists a licensed human sit behind the wheel during testing and even requires state-police supervision, an approach clearly designed to preserve a human focal point for negligence suits.[28] At the federal level, the National Highway Traffic Safety Administration has issued advisory guidance and rolled out multi-billion-dollar initiatives, yet it still has not adopted binding performance standards that would unify the existing patchwork of state regulations.[29] With a regulatory gap in place, courts are more likely to rely on common law principles than wait for Congress to step in.
Extending vicarious liability to machine conduct promotes compensation and deterrence but raises countervailing concerns. Developers warn that open-ended exposure could chill innovation,[30] raise insurance premiums,[31] and slow development of a technology that promises to slash crash rates relative to human drivers.[32] Some commentators propose a no-fault compensation fund modelled on the National Vaccine Injury Compensation Program,[33] arguing that the social gains from widespread automation justify spreading losses across all beneficiaries rather than pinning them on a single unlucky manufacturer.[34] Others advocate for strict enterprise liability, contending that guaranteed compensation is essential for preserving public trust in streets shared with algorithmic drivers.[35] How courts decide to expand existing doctrines or demand new legislation will depend on how they balance deterrence, innovation, and fair compensation for victims.
Several key doctrinal questions still remain. First, the very identity of the “driver” fluctuates across jurisdictions, complicating cross-state fleet management and insurance pricing.[36] Second, courts must determine the standard for reasonable supervision when a human overseer cannot foresee, or even comprehend, every decision made by a black-box[37] neural network.[38] Third, the line between a product defect and negligent supervision is blurry. For example, if an AV crashes in heavy rain, was the root cause a design flaw, inadequate training data, or poor monitoring?[39] Fourth, once federal safety standards are in place, courts will need to decide whether state tort duties that go beyond those regulations are preempted. Fifth, proving causation hinges on access to detailed sensor recordings and machine-learning logs. Without compulsory data-driven rules or presumptions that missing data cut against the holder, plaintiffs may struggle to satisfy even a basic negligence showing.[40] While these gaps do not doom traditional tort theory, each will need careful tailoring to keep the law in step with advancing technology.
Although autonomous decision-making is new, existing tort and agency doctrines have already shown themselves to be remarkably adaptable. Treating the AV as an agent or employee reflects the reality that it carries out its deployer’s agenda, not any self-originated impulses.[41] Viewing deployment as an arrangement with non-delegable duties places liability on the party best equipped to bear and manage the risk.[42] Negligent supervision stops developers from shifting blame to the black-box code they selected, trained, or disregarded.[43] Because federal regulators have stayed on the sidelines, states have begun testing varied operator definitions and oversight rules, leaving courts to refine the law case by case. As cases trickle in, judges will return to tort law’s central inquiry: who could have avoided the harm at the least cost?[44] Given that companies design and profit from autonomous systems, judges are likely to keep viewing them as the ultimate risk bearers.
The central policy challenge is to navigate between two dangers: too little deterrence, which could leave crash victims without a responsible defendant, and too much deterrence, which could keep potentially life-saving automation stuck in perpetual testing. A mix of vicarious liability and negligent supervision doctrines, supplemented by robust data-access requirements and possibly an insurance safety net for major losses, can achieve that equilibrium. In the meantime, lawyers, lawmakers, and scholars must update the language that this centuries-old body of law will use to address a distinctly twenty-first century driver.



Comments