Use-case guide
AI in Autonomous Vehicles & Transportation
Autonomous-vehicle AI is the most regulated AI domain on earth — and the rules come from three layers simultaneously. International: UNECE WP.29 framework (UN R155 cybersecurity, UN R156 software updates, UN R157 ALKS). EU: type-approval regulation 2018/858 plus the AI Act treating AVs as Annex I products. US: federal NHTSA framework plus a state-by-state patchwork (California DMV Autonomous Vehicle Tester Program, Arizona, Texas, Nevada, all with different rules). Add ISO/SAE 21434 cybersecurity, ISO 26262 functional safety, and SAE J3016 levels — and you have a compliance map most teams take a year to build.
For: AV developers (L3-L5), OEMs adding driver-assist, fleet operators, federal/state transport regulators, AV insurance counsel
What's at stake
AVs are high-risk under the EU AI Act via Annex I
Article 6(1) plus Annex I (Machinery, RED, Type-Approval Regulation) covers AI components in vehicles. Conformity assessment must integrate AI Act requirements with the existing Type-Approval Regulation 2018/858 process.
UNECE WP.29 is the global compliance core
UN R155 (cybersecurity), UN R156 (software updates), and UN R157 (ALKS — Automated Lane-Keeping Systems) are binding in 60+ jurisdictions. They establish minimum AI-relevant safety and ops requirements that EU/UK/Japan/Korea all enforce.
US state law dictates testing and deployment
Federal NHTSA pre-empts vehicle design but states control insurance, registration, and on-road testing. California's AV Tester Program plus the new CPUC charter-permit rules for driverless ride-hailing are the most restrictive in the US.
Functional safety + AI safety must be jointly certified
ISO 26262 (functional safety) plus ISO 21448 (SOTIF — safety of the intended functionality) plus ISO 21434 (cybersecurity) plus the AI Act's Article 9 risk-management overlap. Treating any of these in isolation is how AV programmes miss target ship dates by quarters.
Regulations that apply
EU AI Act
LawAI in vehicles is high-risk via Annex I (Type-Approval). Article 6, Annex IX coordination with sectoral law. Conformity assessment integrated into existing EU type-approval.
Where in the text: Article 6(1); Annex I; Annex IX.
UNECE WP.29 — UN R155 / R156 / R157
StandardGlobal minimum requirements for AV cybersecurity, OTA software updates, and ALKS. Mandatory in EU/UK/Japan/Korea/Australia type-approval.
Where in the text: UN R155 §5-7; UN R156 §5-7; UN R157 §6-7.
US NHTSA AV Comprehensive Plan + FMVSS
GuidelineFederal pre-emption on vehicle design plus the AV Comprehensive Plan voluntary submission programme. New FMVSS amendments for AV-specific equipment forthcoming.
Where in the text: NHTSA AV Comprehensive Plan; 49 C.F.R. Part 571 FMVSS.
California DMV AV Tester Programme + CPUC charter
RegulationMost restrictive US state regime. Tester permits, driverless deployment permits, CPUC charter for ride-hailing. Annual disengagement reporting publicly available.
Where in the text: 13 C.C.R. Part 227.00 et seq.; CPUC AV Charter rules.
Do
- ✓Build your AI safety case integrated with ISO 26262 + ISO 21448 + ISO 21434 + AI Act Article 9 — these aren't four separate programmes, they're one.
- ✓Treat the disengagement-data + OTA-update logs as evidentiary records — they will be subpoenaed in any incident litigation.
- ✓Engage with NHTSA, EU AI Office, and your state DMV in parallel for any L4+ deployment. Sequential engagement loses years.
- ✓Document the operational design domain (ODD) explicitly and test/monitor against it — most AV incidents trace to ODD-out-of-distribution operation.
- ✓Plan for a human-takeover or safe-stop fallback even in L4 systems — UN R157 expects it and US plaintiff lawyers will demand it.
Don't
- ✗Don't claim autonomy levels above what your ODD supports — SAE J3016 misuse is now an FTC consumer-deception issue (see Tesla AutoPilot/FSD cases).
- ✗Don't deploy real-time biometric identification of pedestrians for safety purposes in EU public spaces — Article 5(1)(h) of the AI Act bans most uses.
- ✗Don't ship an OTA update without UN R156 conformity — missing this is a type-approval revocation trigger in EU/UK markets.
- ✗Don't treat the safety driver as a compliance shortcut for incomplete testing — California has issued public reports calling out exactly this practice.
- ✗Don't rely on simulation alone for ODD coverage — most jurisdictions now require minimum real-world test mileage before driverless deployment.
Also worth knowing
If you build Driver Monitoring Systems (DMS): EU GSR 2019/2144 made DMS mandatory in new cars from July 2024; emotion-recognition aspects need to navigate Article 5(1)(f) of the AI Act (banned in workplaces — driving for hire is the active line). For drones and unmanned aircraft: EU EASA Regulation 2019/947 applies separately; the AI Act doesn't carve them out.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.