Showing posts with label NHTSA. Show all posts
Showing posts with label NHTSA. Show all posts

Friday, September 18, 2026

NHTSA Sends FMVSS 108 for ADS NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOT’s National Highway Transportation Safety Administration (NHTSA) on “Modernization of FMVSS 108 to Accommodate ADS”.  

According to the 2026 Unified Agenda entry for this rulemaking: 

“The Federal Motor Vehicle Safety Standard that regulates vehicle lighting (FMVSS 108) includes requirements that assume a human driver and manual controls, references the location of a human driver, or specifies the operation of manual controls to effectuate testing for compliance with the standards. This rulemaking would address the applicability of the standard for vehicles that are equipped with automated driving systems (ADS) and lack manual controls. This rulemaking would maintain the level of safety performance required by the standard.” 

While Congress has still not been able to develop comprehensive legislation on automated driving system safety, NHTSA continues to deal with the nuts and bolts of adopting current Federal Motor Vehicle Safety Standard regulations so that they continue to apply to ADS vehicles already being put on the road. 

Saturday, June 13, 2026

OMB Approves NHTSA FMVSS 135 ADS NPMR

This rulemaking was not listed in the Spring 2025 Unified Agenda. This is part of NHTSA’s ongoing effort to update existing FMVSS to include (where applicable) automated driving systems equipped vehicles; see here for example.  

For this rulemaking, I would expect NHTSA to address, for instance, § 571.135 S5.3.1 states that: “The service brakes shall be activated by means of a foot control.” An ADS equipped vehicle may not be equipped with a foot brake control, requiring a change in that language. Because of the increased importance of electronic controls in an ADS-equipped vehicle, I would like to see (but do not really expect to see) some mention of cybersecurity controls in the revised standards. 

Lacking cybersecurity provisions, I would not expect to cover this rulemaking in any detail. I will at least mention the NPRM’s publication in the appropriate Short Takes post. 

Friday, April 11, 2025

OMB Approves NHTSA Automated Driving System ICR

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request (ICR) revision from the DOT’s National Highway Transportation Safety Administration (NHTSA) on “Automated Driving Systems 2.0: A Vision for Safety”. The revised burden estimate shows a decrease in the number of reports and the number of expected burden hours.

The table below shows the change in the burden estimate.

 

NHTSA reported that:

“The currently approved collection estimated 20 respondents per year, each responding once in that year. The burden associated with disclosure recommendations via a VSSA would be 600 hours per respondent. The annual burden associated with the information collection was calculated as 12,000 hours and $1,168,320 in labor costs. The revisions estimate four entities will publish a VSSA every year and will publish only once in the three-year period. This decrease is a result of review of the submissions for the currently approved collection and a review of the entities currently in the Automated Driving System industry.”

Friday, December 20, 2024

OMB Approves NHTSA Automated Driving System NPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the DOT’s National Highway Transportation Safety Administration (NHTSA) on “Exemption and Demonstration Framework for Automated Driving Systems”. The NPRM was submitted to OIRA on October 21st, 2024. NHTSA published an advanced notice of proposed rulemaking (ANPRM) on this topic on December 3rd, 2020.

According to the Fall 2024 Unified Agenda entry for this rulemaking:

“This notice would propose a framework for the review and assessment of Automated Driving System (ADS)-equipped vehicles, in order to evaluate operations or requests for exemptions involving such technologies while also informing the agency's approach to future rulemaking and oversight.”

Monday, November 18, 2024

OMB Approves NHTSA Pedestrian Protection Final Rule

Friday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule from the DOT’s National Highway Transportation Safety Administration (NHTSA) on “New Car Assessment Program Pedestrian Protection”. NHTSA sent the proposed final rule to OIRA on September 10th, 2024. NHTS published a request for comments on the rulemaking on May 5th, 2023. This rulemaking was not listed in the Spring 2023 Unified Agenda.

I am not likely to provide any detailed coverage on the publication of this rule. I am mentioning it because it will be another expansion of NHTSA vehicle automation requirements without any significant regulatory requirements for cybersecurity protections of such systems. I do expect to announce the publication of the final rule in the appropriate Short Takes post when it is published.

Thursday, November 7, 2024

Review – NHTSA Publishes Crash Avoidance HMI 60-day ICR Notice

Today, DOT’s National Highway Traffic Safety Administration (NHTSA) published a 60-day information collection request (ICR) notice in the Federal Register (89 FR 88342-88346) for a new ICR for “Crash Avoidance Warning System Human-Machine Interface (HMI) Research”. This ICR will support a one-time research study of drivers' interactions with crash avoidance technology with different human-machine interface (HMI) characteristics. NHTSA proposes the following burden estimate for this new ICR:


Public Comments

NHTSA is soliciting public comments on this ICR notice. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2024-0070). Comments should be submitted by January 6th, 2025.

 

For more details about the information collection, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nhtsa-publishes-crash-avoidance-hmi - subscription required.

Tuesday, October 22, 2024

NHTSA Sends Automated Driving System NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOT’s National Highway Traffic Safety Administration (NHTSA) on “Exemption and Demonstration Framework for Automated Driving Systems”.

According to the entry in the Spring 2024 Unified Agenda for this rulemaking:

“This notice would propose a framework for the review and assessment of Automated Driving System (ADS)-equipped vehicles, in order to evaluate operations or requests for exemptions involving such technologies while also informing the agency's approach to future rulemaking and oversight.”

I will be watching this rulemaking for cybersecurity provisions.

Tuesday, June 11, 2024

Review - NHTSA Publishes Connected Driving 30-Day ICR Notice

Yesterday, the DOT’s National Highway Transportation Safety Administration (NHTSA) published a 30-day information collection request (ICR) in the Federal Register (89 FR 49268-49273) for a new data collection on “Human Interaction With Driving Automation Systems”. The 60-day ICR notice was published on December 12th, 2023. According to today’s notice summary: “The proposed collection of information described below supports research addressing safety-related aspects of drivers' interactions with driving automation systems.”



NHTSA is soliciting public comments on this data collection. Comments may be submitted by visiting today’s notice and clicking on the ‘Submit a Formal Comment’ label on the top of the page. Comments are due by July 11th, 2024.

 

For more details about today’s notice, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nhtsa-publishes-connected-driving - subscription required.

Friday, January 5, 2024

Review - NHTSA Publishes Impaired Driving Prevention Technology ANPRM

Today, DOT’s National Highway Transportation Safety Administration (NHTSA) published an advanced notice of proposed rulemaking (ANPRM) for “Advanced Impaired Driving Prevention Technology” in the Federal Register (89 FR 830-857). NHTSA is considering a rulemaking that would gather the information necessary to develop performance requirements and require that new passenger motor vehicles be equipped with advanced drunk and impaired driving prevention technology through a new Federal Motor Vehicle Safety Standard (FMVSS). This rulemaking is required by §24220(c) of the Infrastructure Investment and Jobs Act (PL 117-58, 135 STAT. 832).

NHTSA is seeking information about such technologies that may currently be available or are under development. The series of questions posed by this ANPRM include specific questions dealing with cybersecurity requirements and tools that may be required by the rulemaking.

Public Comments

NHTSA is soliciting public comments on the ANPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2022-0079). Comments should be submitted by March 5th, 2024.

Commentary

NHTSA is late with this ANPRM. Section 24220 requires this rulemaking to be completed by November 15th, 2024; NHTSA will be hard pressed to develop a new safety standard by that time. While Congress did give NHTSA an out for delaying the final rule {§24220(e)}, I am fairly certain that those processes were designed to deal with delays in technology development. With the publication of this ANPRM, NHTSA is just now publicly looking for information about the state of the technology. The federal government is becoming increasingly inefficient, in Congress because of political issues and in the executive branch due to underfunding and understaffing (which appear to be the result of congressional inefficiencies).

 

For more information about this rulemaking, including a list of the cybersecurity questions that NHTSA wants answered, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nhtsa-publishes-impaired-driving - subscription required.

Thursday, July 1, 2021

OMB Approves NHTSA Emergency ICR for ADS Incident Reporting

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an emergency information collection request (ICR) for “Incident Reporting for Automated Driving Systems (ADS) and Level 2 Advanced Driver Assistance Systems (ADAS)”. This ICR is in support of a National Highway Transportation Safety Administration (NHTSA) plan to “issue a Standing General Order requiring manufacturers and operators of vehicles equipped with ADS or Level 2 ADAS to report crashes where the systems were engaged or in use immediately before the crash.”

According to the supporting document [DOCX download link] filed with OIRA, there will be two different types of reports required by the new Order, depending on the severity of the incident. NHTSA will require the first type of report for “any crash involving an ADS or Level 2 ADAS equipped vehicle that results in any individual being transported to a hospital for medical treatment, a fatality, a vehicle tow-away, or an air bag deployment or that involves a vulnerable road user” (pg 1). These type crashes will require a report within 1-day with a 10-day follow-up report using the same form.

The second type reporting will be required when a lesser severity crash occurs, but still involves “nonetheless involves personal injury or property damage” (pg 2). Manufacturers will be required to submit these reports to NHTSA on the 15th of the month immediately following the accident, with a follow-up report the following month. Monthly submission would be required even if no accidents were reported.

Additionally, NHTSA included in the burden estimate (table 1, pg 11) entries for training requirements and setting up a MAP Account, the system NHTSA has for automotive manufacturers to report automotive defects and recalls.

The table below shows the burden estimate for this ICR. A single form [.PNG download link] will be used for each of the reports.

 

Number of Responses

Number of Respondents

Hours per Response

Total Burden (hrs)

1-day Reports

3,410

30

2

6,820

10-day Follow-up

3,410

30

1

3,410

1-Month Reports

1,320

110

1.01

1,329

Training

20

20

40

800

MAP Account

85

85

2

170

There is one oddity in the narrative for this ICR, it refers to ‘manufacturers and operators’ in some place and just ‘manufacturers’ in others. We will have to see the General Order to make better sense of the issue.

One final item of interest; there is no mention of ‘cyber’, ‘cyberattack’ or ‘cybersecurity’ that I can find in any of the documentation associated with this ICR. I am not sure if that is due to short-sightedness on the part of NHTSA or whether it is a conscious decision to avoid that topic in the ICR. It could be addressed more specifically in the General Order.

Tuesday, January 12, 2021

NHTSA Publishes Cybersecurity Request for Comments

Today the DOT’s National Highway Transportation Safety Administration (NHTSA) published a request for comments in the Federal Register (86 FR 2481-2486) on its draft update [.PDF Download] for their “Cybersecurity Best Practices for the Safety of Modern Vehicles”. This is an update of the 2016 version of the document based upon ongoing research and comments received from government agencies, industry and the public on the original document [.PDF download].

In today’s notice NHTSA makes it clear that it continues to believe that adoption of these best practices should be voluntary. They also specifically note that they deal with safety aspects of cybersecurity. Safety is the NHTSA mandate not privacy.

New Guidance

The new draft includes the following ‘new’ best practices:

[G.6] Manufacturers should consider the risks associated with sensor vulnerabilities and potential sensor signal manipulation efforts such as GPS spoofing, road sign modification, Lidar/Radar jamming and spoofing, camera blinding, or excitation of machine learning false positives.

[G.9] Clear cybersecurity expectations should be specified and communicated to the suppliers that support the intended protections.

[G.10] Manufacturers should maintain a database of operational software components used in each automotive ECU, each assembled vehicle, and a history log of version updates applied over the vehicle's lifetime; and Manufacturers should track sufficient details related to software components, such that when a newly identified vulnerability is identified related to an open source or off-the-shelf software, manufacturers can quickly identify what ECUs and specific vehicles would be affected by it.

[G.12] Manufacturers should evaluate all commercial off-the-shelf and open-source software components used in vehicle ECUs against known vulnerabilities.

[G.22] Best practices for secure software development should be followed, for example as outlined in NIST 8151 and ISO/SAE 21434.

[G.23] Manufacturers should actively participate in automotive industry-specific best practices and standards development activities through Auto-ISAC and other recognized standards development organizations.

[G.30] Commensurate to assessed risks, organizations should have a plan for addressing newly identified vulnerabilities on consumer-owned vehicles in the field, inventories of vehicles built but not yet distributed to dealers, vehicles delivered to dealerships but not yet sold to consumers, as well as future products and vehicles.

[G.40] Any connection to a third-party device should be authenticated and provided with appropriate limited access.

[T.7] The use of global symmetric keys and ad-hoc cryptographic techniques for diagnostic access should be minimized.

[T.8] Vehicle and diagnostic tool manufacturers should control tools' access to vehicle systems that can perform diagnostic operations and reprogramming by providing for appropriate authentication and access control.

[T.12] Such logs that can be aggregated across vehicles should be periodically reviewed to assess potential trends of cyber-attacks.

[T.13] Manufacturers should treat all networks and systems external to a vehicle's wireless interfaces as untrusted and use appropriate techniques to mitigate potential threats.

[T.22] Maintain the integrity of OTA updates, update servers, the transmission mechanism and the updating process in general.

[T.23] Take into account, when designing security measures, the risks associated with compromised servers, insider threats, men-in-the-middle attacks, and protocol vulnerabilities.

Public Comments

NHTSA is soliciting public comments on this draft document. Comments may be submitted via the Federal eRulemaking Portal (www.regulations.gov; Docket #NHTSA-2020-0087). Comments should be submitted by March 15th, 2020.

Commentary

Guidance documents such as this have two major shortcomings. First, and foremost, since they are self-pronouncedly voluntary, there is no way to ensure that they are being followed. Second, even if a company were to try to adhere to this guidance, without an outside eye to watch over how the guidance is implemented to ensure that the company really understands what it is doing or trying to do from a cybersecurity perspective, there will be significant gaps in the resulting cybersecurity coverage.

This is not privacy or money that NHTSA is trying to protect. You can not go back and require a company that failed to adequately implement these best practices make an affected customer whole by replacing mangled limbs or reanimating dead bodies. Lack of cybersecurity in moving vehicles is going to have physical consequences in the real world. Monetary damages from lawsuits are not going to be an adequate (and will be a very delayed) response to cybersecurity failures.

Thursday, January 7, 2021

OMB Approves NHTSA Cybersecurity Request for Comments

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice from the DOT’s National Highway Transportation Safety Administration (NHTSA) for “Request for Comments on Cybersecurity Best Practices for the Safety of Modern Vehicles”. Documents such as this are not listed in the Unified Agenda, so there is no public information about what may be included. This type of document is typically a prequel [sorry that should have been 'prelude'] to the initiation of rulemaking.

I would expect this to be published in the Federal Register in the next week or two.

Friday, December 4, 2020

NHTSA Sends Cybersecurity Comment Notice to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a copy of “Request for Comments on Cybersecurity Best Practices for the Safety of Modern Vehicles” for review from the DOT’s National Highway Transportation Safety Administration (NHTSA). This pre-rulemaking activity was not published in the 2020 Spring Unified Agenda, so there are no publicly available details on this document.

It is interesting to note that the title does not appear to restrict the request for comments to just automated driving systems, but we will have to wait for NHTSA to publish the document in the Federal Register to be sure. I do not expect OIRA to approve this document before January 21st, 2021; nothing to do specifically with the change in administrations, just a normal turnaround time at OIRA.


Tuesday, November 3, 2020

NHTSA Sent Automated Driving Systems ANPRM to OIRA for Review

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an advanced notice of proposed rulemaking (ANPRM) from the DOT’s National Highway Transportation Safety Administration (NHTSA) concerning “Safety Principles for Automated Driving Systems”.

According to the Spring 2020 Unified Agenda abstract for this rulemaking:

“This notice solicits comments on regulatory approaches to motor vehicles equipped with Automatic Driving System (ADS). The agency seeks public comments on the creation of a safety framework for objectively and transparently assessing and validating the success of each ADS vehicle or developer in designing safety into its vehicles. More specifically, it asks commenters about developing and establishing a regulatory approach such as amending Federal Motor Vehicle Safety Standards (FMVSS) or developing alternative safety regulations relating to ADS vehicle performance.”

 Commentary

We are starting to get to that point in time where we have to consider whether the current Administration’s OMB will complete action on this rulemaking. In the normal course of events, it would not be beyond ‘reasonable’ for OIRA action on this rulemaking to be delayed beyond January 21st, 2021. If Biden is elected, I do not expect that this would be one of the rulemakings that the Trump Administration would try to press through to early, lame duck approval.

On the other hand, if this ANPRM were to be published before January 21st, I do not expect that there would be any serious opposition to the continuation of the rulemaking in the Biden Administration. In short, this is an issue that the Federal government is going to have to address in the regulatory near term. The face of the final rule would almost certainly be different under Trump or Biden administrations, but this early stage of the rulemaking is more about collecting information than actually regulating.

Thursday, September 24, 2020

Bills Introduced – 9-23-20

 Yesterday, with both the House and Senate in session, there were 51 bills introduced. One of those bills may receive additional coverage in this blog:

HR 8350 To amend title 49, United States Code, regarding the authority of the National Highway Traffic Safety Administration over highly automated vehicles, to provide safety measures for such vehicles, and for other purposes. Rep. Latta, Robert E. [R-OH-5]

I will be watching this bill for language and definitions that address cybersecurity issues with automated vehicles. There is a short news article on this legislation on TheHill.com.

Saturday, March 14, 2020

OMB Approves NHTSA Automated Driving System NPRM


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the DOT’s National Highway Transportation Safety Administration (NHTSA) concerning “Occupant Protection for Automated Driving Systems”.

The 2019 Fall Unified Agenda entry for this rulemaking notes:

“This action proposes to amend crashworthiness regulations that may be necessary to facilitate the certification of motor vehicles equipped without driver controls. The agency published a Federal Register notice on January 18, 2018, requesting comment on existing regulatory barriers that may block the introduction and certification of ADS-equipped vehicles, particularly those without human controls. In response to comments received from the January notice, the agency initiated this NPRM to begin the rulemaking process. NHTSA will consider comments received from this notice, agency research, stakeholder engagement, and internal agency analysis to remove crashworthiness-related regulatory barriers.”

I wrote about the 2018 request for comments.

Tuesday, May 28, 2019

NHTSA Publishes Automated Driving Systems ANPRM


Today the DOT’s National Highway and Traffic Safety Administration (NHTSA) published an advance notice of proposed rulemaking (ANPRM) in the Federal Register (84 FR 24433-24449) concerning possible changes to the Federal Motor Vehicle Safety Standards (FMVSS) that would be necessary to support the introduction of automated driving systems (ADS-DV). This rulemaking would specifically address changes to the 100-series (crash avoidance) FMVSS.

Barriers in FMVSS


The current rulemaking will seek to address barriers in the current crash avoidance FMVSS that would impede the introduction of ADS-DV designed without traditional manual controls. NHTSA has identified three categories of such impedances:

The standard requires a manual control.
The standard specifies how the agency will use manual controls in the regulatory description of how it will test.
The definition or use of terms (e.g., “driver”) in the FMVSS that assume human control of vehicles.

The first two categories are addressed in this rulemaking. The last will be common to other sections of the FMVSS (which will be covered in separate rulemakings), so NHTSA is considering a completely separate rulemaking for the definitions problem.

Manual Control


After a brief discussion of one of the potential barriers in the FMVSS to ADS-DV introduction, NHTSA proposes four possible solutions to the manual control issue:

First, if the required control is necessary for motor vehicle safety on all vehicles, NHTSA would retain the requirement for all vehicles, even if that requires potentially redundant technologies for certain ADS-DVs without traditional manual controls.
Second, if the required control is no longer necessary for motor vehicle safety for any vehicle, NHTSA could remove or otherwise modify the requirement, if permitted to by law.
Third, if the required control is still necessary for motor vehicle safety for traditional vehicles, but not necessary for the safety of ADS-DVs without traditional manual controls, NHTSA could retain the requirement only for traditional vehicles and, if permitted by law, exclude ADS-DVs without manual controls.
Fourth, if the required control is necessary for motor vehicle safety, but a different control (i.e., a non-human-actuated control) would be necessary for an ADS-DV to perform the same function, NHTSA may retain the existing requirement for traditional vehicles, but have a separate, different control or equipment requirement for ADS-DVs without traditional manual controls.

Testing


Currently, the FMVSS “outline performance requirements that must be met under certain test procedures and NHTSA will conduct compliance verification tests in accordance with these procedures”. Where the existing language requires the use of manual controls that may not exist in ADS-DV these requirements would impede the introduction of ADS-DV. Removing these impedances will almost certainly require the development of new testing methods.

NHTSA has identified the following potential approaches to this testing dilemma:

Normal ADS-DV operation;
Test Mode with Pre-Programmed Execution (TMPE);
Test Mode with External Control (TMEC);
Simulation;
Technical Documentation for System Design and/or Performance Approach; and
Use of Surrogate Vehicle with Human Controls

Questions


The ANPRM provides a table that lists the current crash prevention FMVSS provisions that may impeded the introduction of ADS-DV. NHTSA is requesting comments on the general approaches to the manual control and testing problems identified above. It also proposes a series of questions (here, here, here, here, here, here, and here)   that it would like commenters to address.

The list of questions includes only two that address (even broadly) cybersecurity issues. They are:

22. How could vehicle-based electronically accessible libraries for conducting FMVSS testing be developed in a way that would allow NHTSA to access the system for compliance testing but not allow unauthorized access that could present a security or safety risk to an ADS-DV?

27. Could a means of manual control be developed that would allow NHTSA to access the system for compliance testing but not allow unauthorized access that could present a security or safety risk to an ADS-DV?

Comments on this rulemaking are due by July 29th, 2019. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2019-0036).

Commentary


There is a lot of interesting problems identified in this rulemaking that are going to have a profound impact on the introduction of automated driving systems. To add to the complexity, the fact that NHTSA is considering at least two (probably 3) more rulemakings addressing FMVSS compliance issues and it becomes clear that engineering for these ADS-DV systems is much further along that the regulatory scheme. Inevitably, these regulatory changes are going to cause additional problems for the engineers.

I continue to be concerned with how NHTSA is apparently glossing over the cybersecurity issue in their regulatory schema. Acknowledging that there are effectively no current cybersecurity requirements in the FMVSS, NHTSA needs to start the public comment process on how such requirements should be addressed in any modified  FMVSS requirements supporting ADS-DV introduction. Since automated controls are not going to have driver backup in vehicles designed without manual controls, security systems and requirements for those automated controls is going to be even more important than in existing cyber-augmented vehicles.

I applaud NHTSA for learning the lesson from the Volkswagen diesel mileage testing fiasco and recognizing that any automated testing program needs to be protected from on-board gaming of the test. I just wish that it could be as forward thinking in identifying potential requirements in the FMVSS for general cybersecurity protections for the vehicle.

Thursday, April 18, 2019

OMB Approves two Automated Driving Rules


Earlier this week the OMB’s Office of Information and Regulatory Affairs (OIRA) approved two advanced notices of proposed rulemaking (ANPRMs) from DOT agencies starting the regulatory process on two separate automated vehicle regulatory actions. The first was a rulemaking from the National Highway Transportation Safety Administration (NHTSA) on “Removing Regulatory Barriers for Automated Driving Systems”. The second was from the Federal Motor Carrier Safety Administration (FMCSA) on “Safe Integration of Automated Driving Systems-Equipped Commercial Motor Vehicles”.

Both of these rulemaking submissions were approved pretty quickly. The NHTSA ANPRM was submitted on March 14th, 2019 and the FMCSA ANPRM on March 21st, 2019. ANPRM’s are the first step in the rulemaking process and typically propose a list of questions that the agency would like answered by the regulated and affected communities before they actually propose regulatory action.

There is no telling when these ANPRMs will actually be published in the Federal Register. There is no procedural reason that it should be more than a couple of days, Both rulemakings were approved by OIRA ‘consistent with change’ so I suspect that it will probably be at least a month before these ANPRMs are published given the rulemaking history of the Trump Administration.

Tuesday, March 19, 2019

NHTSA Publishes Two Automated Driving System Petitions


Today the DOT’s National Highway Transportations Safety Administration (NHTSA) published two notices in the Federal Register (84 FR 10172-10182 and 84 FR 10182-10191) requesting public comments on petitions for exemptions from Federal Motor Vehicle Safety Standards (FMVSS) for two fully-automated-driving vehicles. The first is for an autonomous delivery vehicle from Nuro, Inc. The second is for a driverless passenger vehicle from General Motors.

Nuro Petition


The Nuro petition is for a low-speed delivery vehicle without human occupants. It requests exemption from the following FMVSS standards:

• FMVSS #500 – exemption from rear view mirror requirements;
• FMVSS #250 – exemption from windshield requirements;
FMVSS #111 – exemption from back-up camera requirements.

The petition is limited in scope because the intended Nuro vehicle is already exempt from most FMVSS standards for a normal passenger vehicle because it is a low-speed vehicle as defined under 49 CFR 571.3.

GM Petition


The GM petition is for a passenger vehicle in limited service. It would have no provisions for an occupant to take control of the vehicle during operation. It requests exemption from the following FMVSS standards:

FMVSS #101 – exemption from motor vehicle controls, telltales and indicators requirements;
FMVSS #102 – exemption from transmission shift position sequence, starter interlock, and transmission braking effect requirements;
FMVSS #108 – exemption from headlamp switch requirements;
FMVSS #111 – exemption from rearview mirror requirements;
FMVSS #114 – exemption from parking brake, service brake or transmission gear selection test requirements;
FMVSS #124 – exemption from return of the throttle to the idle position requirements;
FMVSS #126 – exemption from driver loss of directional control requirements;
FMVSS #135 – exemption from human breaking control requirements;
FMVSS #138 – exemption from tire pressure warning requirements;
FMVSS #141 – exemption from gear shift selector test requirements;
FMVSS #203, #204, and #207 – exemption from steering wheel impact test requirements;
FMVSS #208 and #214 – exemption from drivers position crash-test requirements; and
FMVSS #226 – exemption from airbag indicator requirements;

Public Comments


NHTSA is soliciting public comments on the petitions. Comments are required to be submitted by May 20th, 2019. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2019-0017, Nuro petition; and NHTSA-2019-0016, GM petition).

Commentary


An interesting component of both of these petitions is that they are for electric vehicles. That does not seem to matter much except that both petitions include reference to regulatory exemptions for ‘low emission vehicles’. Congress gave DOT authority (49 USC 30113) to ease the introduction of ‘low-emission vehicles’ by providing temporary exemptions to vehicle safety standards. Both petitions are using the argument from §30113(b)(3)(B)(iii) that “the exemption would make easier the development or field evaluation of a new motor vehicle safety feature providing a safety level at least equal to the safety level of the standard”; the new ‘motor vehicle safety feature’ being the autonomous operation system.

While avoiding the well known and documented safety problems associated with human drivers, autonomous vehicle operating systems are going to present their own problems. Both petitioners are making the point that to be able to identify (the necessary precursor to fixing) problems of their systems in real-world operations is the only way to move these systems into full-scale production. In many ways, this seems to be a valid argument, except….

The big problem missing from the discussion in either petition is the cybersecurity of their operating systems. A major reason for this is that NHTSA (and at base, Congress) have failed to explicate how they expect developers to protect these systems. With no federal regulatory requirements in existence, neither applicant is under any obligation to provide information on how (or even if) they are addressing the cybersecurity issue. This does not provide me with a warm fuzzy feeling.

The current crop of autonomous vehicles undergoing real-world testing still have the capability of human intervention to overcome software issues of malware or bad code. Granted that oversight has not been perfect by any stretch of the imagination, but it is there. These two proposals specifically and graphically have removed that intervention; a necessary next-step in the development of truly autonomous vehicles. The question, however, is are we ready to take that next step when we do not yet have a definition of the cybersecurity requirements for these systems, or a way to evaluate the efficacy of the cybersecurity systems put into play (whatever they are). Before we take the next step, we need to have a handle on, or at least a definition of the cybersecurity of these systems.

Monday, March 18, 2019

NHTSA Barriers to Automated Driving Systems ANPRM to OMB


On Thursday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received from DOT’s National Highway Traffic Safety Administration (NHTSA) an advanced notice of proposed rulemaking (ANPRM) on “Removing Regulatory Barriers for Automated Driving Systems” for review.

The Fall 2018 Unified Agenda listing for this rulemaking explains:

“This notice seeks comment on existing motor vehicle regulatory barriers to the introduction and certification of automated driving systems. NHTSA is developing the appropriate analysis of requirements that are necessary to maintain existing levels of safety while enabling innovative vehicle designs and removing or modifying those requirements that would no longer be appropriate if a human driver will not be operating the vehicle. NHTSA previously published a Federal Register notice requesting public comment on January 18, 2018.”

 
/* Use this with templates/template-twocol.html */